<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/"><channel><title>Kendiv's Box - 深入探索Windows系统</title><link>http://blog.csdn.net/kendiv/category/88780.aspx</link><description>有关Windows系统内核的文章、对Windows系统机制的剖析及其相关应用</description><dc:language>zh-CN</dc:language><lastUpdateTime>Fri, 04 Apr 2008 02:04:17 GMT</lastUpdateTime><ttl>60</ttl><item><dc:creator>Kendiv</dc:creator><title>优先级反转+解决方案</title><link>http://blog.csdn.net/kendiv/archive/2007/09/18/1788966.aspx</link><pubDate>Tue, 18 Sep 2007 01:33:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2007/09/18/1788966.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/1788966.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2007/09/18/1788966.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/1788966.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=1788966</trackback:ping><description>简要介绍了什么是优先级反转，产生的原因及其解决方案。&lt;img src ="http://blog.csdn.net/kendiv/aggbug/1788966.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>Windows内核调试器原理浅析</title><link>http://blog.csdn.net/kendiv/archive/2007/05/01/1594180.aspx</link><pubDate>Tue, 01 May 2007 15:07:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2007/05/01/1594180.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/1594180.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2007/05/01/1594180.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/1594180.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=1594180</trackback:ping><description>简单分析了WinDBG，并于SoftICE进行了对比。&lt;img src ="http://blog.csdn.net/kendiv/aggbug/1594180.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>(转载)绕过Copy-On-Write机制安装全局Hook</title><link>http://blog.csdn.net/kendiv/archive/2005/10/26/517233.aspx</link><pubDate>Wed, 26 Oct 2005 21:53:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/10/26/517233.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/517233.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/10/26/517233.aspx#Feedback</comments><slash:comments>2</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/517233.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=517233</trackback:ping><description>绕过Copy-On-Write机制安装全局Hook
&lt;img src ="http://blog.csdn.net/kendiv/aggbug/517233.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>(转载)Raising The Bar For Windows Rootkit Detection</title><link>http://blog.csdn.net/kendiv/archive/2005/08/29/467720.aspx</link><pubDate>Mon, 29 Aug 2005 21:43:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/08/29/467720.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/467720.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/08/29/467720.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/467720.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=467720</trackback:ping><description>讨论Windows下内核级Rootkit的检测技术及其原理，以Shadow Walker工具为例。本文中分析内存的部分很具有价值。&lt;img src ="http://blog.csdn.net/kendiv/aggbug/467720.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>(转载)检测并禁用隐藏服务</title><link>http://blog.csdn.net/kendiv/archive/2005/05/31/384663.aspx</link><pubDate>Tue, 31 May 2005 07:28:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/31/384663.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/384663.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/31/384663.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/384663.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=384663</trackback:ping><description>检测并禁用隐藏服务&lt;img src ="http://blog.csdn.net/kendiv/aggbug/384663.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第一章（补充：PDB格式）（4）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/25/380950.aspx</link><pubDate>Wed, 25 May 2005 23:37:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/25/380950.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/380950.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/25/380950.aspx#Feedback</comments><slash:comments>41</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/380950.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=380950</trackback:ping><description>讨论微软的.pdb和.dbg符号文件的内部格式，并给出了可解析这两种格式的示例程序&lt;img src ="http://blog.csdn.net/kendiv/aggbug/380950.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第七章（4）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/23/379245.aspx</link><pubDate>Mon, 23 May 2005 23:44:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/23/379245.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/379245.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/23/379245.aspx#Feedback</comments><slash:comments>8</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/379245.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=379245</trackback:ping><description>Windows 2000的对象管理&lt;img src ="http://blog.csdn.net/kendiv/aggbug/379245.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第七章（3）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/22/378395.aspx</link><pubDate>Sun, 22 May 2005 23:04:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/22/378395.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/378395.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/22/378395.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/378395.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=378395</trackback:ping><description>Windows 2000的对象管理&lt;img src ="http://blog.csdn.net/kendiv/aggbug/378395.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第七章（2）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/22/377947.aspx</link><pubDate>Sun, 22 May 2005 01:32:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/22/377947.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/377947.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/22/377947.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/377947.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=377947</trackback:ping><description>Windows 2000的对象管理&lt;img src ="http://blog.csdn.net/kendiv/aggbug/377947.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第一章（补充：PDB格式）（3）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/21/377309.aspx</link><pubDate>Sat, 21 May 2005 04:43:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/21/377309.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/377309.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/21/377309.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/377309.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=377309</trackback:ping><description>讨论微软的.pdb和.dbg符号文件的内部格式，并给出了可解析这两种格式的示例程序。&lt;img src ="http://blog.csdn.net/kendiv/aggbug/377309.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第一章（补充：PDB格式）（2）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/21/377308.aspx</link><pubDate>Sat, 21 May 2005 04:40:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/21/377308.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/377308.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/21/377308.aspx#Feedback</comments><slash:comments>0</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/377308.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=377308</trackback:ping><description>讨论微软的.pdb和.dbg符号文件的内部格式，并给出了可解析这两种格式的示例程序。&lt;img src ="http://blog.csdn.net/kendiv/aggbug/377308.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第一章（补充：PDB格式）（1）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/21/377307.aspx</link><pubDate>Sat, 21 May 2005 04:37:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/21/377307.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/377307.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/21/377307.aspx#Feedback</comments><slash:comments>5</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/377307.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=377307</trackback:ping><description>讨论微软的.pdb和.dbg符号文件的内部格式，并给出了可解析这两种格式的示例程序。&lt;img src ="http://blog.csdn.net/kendiv/aggbug/377307.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第七章（1）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/20/377229.aspx</link><pubDate>Fri, 20 May 2005 23:37:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/20/377229.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/377229.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/20/377229.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/377229.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=377229</trackback:ping><description>Windows 2000的对象管理&lt;img src ="http://blog.csdn.net/kendiv/aggbug/377229.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第六章（7）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/15/374929.aspx</link><pubDate>Sun, 15 May 2005 02:29:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/15/374929.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/374929.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/15/374929.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/374929.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=374929</trackback:ping><description>在用户模式下调用内核API函数
&lt;img src ="http://blog.csdn.net/kendiv/aggbug/374929.aspx" width = "1" height = "1" /&gt;</description></item><item><dc:creator>Kendiv</dc:creator><title>《Undocumented Windows 2000 Secrets》翻译 --- 第六章（6）</title><link>http://blog.csdn.net/kendiv/archive/2005/05/14/374707.aspx</link><pubDate>Sat, 14 May 2005 20:04:00 GMT</pubDate><guid>http://blog.csdn.net/kendiv/archive/2005/05/14/374707.aspx</guid><wfw:comment>http://blog.csdn.net/kendiv/comments/374707.aspx</wfw:comment><comments>http://blog.csdn.net/kendiv/archive/2005/05/14/374707.aspx#Feedback</comments><slash:comments>1</slash:comments><wfw:commentRss>http://blog.csdn.net/kendiv/comments/commentRss/374707.aspx</wfw:commentRss><trackback:ping>http://tb.blog.csdn.net/TrackBack.aspx?PostId=374707</trackback:ping><description>在用户模式下调用内核API函数&lt;img src ="http://blog.csdn.net/kendiv/aggbug/374707.aspx" width = "1" height = "1" /&gt;</description></item></channel></rss>